# Pull image from private registry using service DNS name

**URL:** <https://discuss.kubernetes.io/t/pull-image-from-private-registry-using-service-dns-name/13740>\
**Category:** General Discussions\
**Created:** [November 18, 2020, 9:07am UTC](https://discuss.kubernetes.io/t/pull-image-from-private-registry-using-service-dns-name/13740 "2020-11-18T09:07:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefan.loerwald](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/stefan.loerwald/32/6277_2.png) [@stefan.loerwald](https://discuss.kubernetes.io/u/stefan.loerwald)\
**Post date:** [November 18, 2020, 9:07am UTC](https://discuss.kubernetes.io/t/pull-image-from-private-registry-using-service-dns-name/13740/1 "2020-11-18T09:07:23Z")

</div>

### Cluster information:

Kubernetes version: v1.18.8  
Cloud being used: bare-metal  
Installation method: docker-for-win  
Host OS: Windows 10 20H2  
CNI and version: ?  
CRI and version: ?

(question also asked on stackoverflow [here](https://stackoverflow.com/questions/64889838/k8s-pull-image-from-private-registry-using-service-dns-name))

I have a `registry:2` deployed as pod in my kubernetes cluster (running on docker-for-win, WSL2). I have two services for this pod as shown below:

```auto
apiVersion: v1
kind: Service
metadata:
  name: registry-external
spec:
  type: NodePort
  selector:
    app: registry
  ports:
    - protocol: TCP
      port: 5000
      nodePort: 32020
---
apiVersion: v1
kind: Service
metadata:
  name: registry
spec:
  selector:
    app: registry
  ports:
    - name: http
      protocol: TCP
      port: 2100
      targetPort: 5000

```

So the first one for reaching the registry from outside the cluster (on port 32020, so I can `docker login localhost:32020` on the host machine) and one for reaching the registry from the inside (on port 2100).

The login from outside works just fine. I’ve verified by `nslookup registry` on the cluster, that the registry should be reachable on `registry.default.svc.cluster.local` . So I created my image pull secrets with

```json
{
    "auths": {
        "registry.default.svc.cluster.local:2100": {
            "auth": "......"
        },
    ...
}

```

When I try to deploy a pod with this image pull secret and image `registry.default.svc.cluster.local:2100/animage:latest` it fails with

```auto
dial tcp: lookup registry.default.svc.cluster.local on 192.168.65.1:53: no such host

```

I’m puzzled by this: shouldn’t the URL be valid at time of image pull?
